Private, cryptographically secure password tool

Password Generator

Create strong random passwords, memorable passphrases or PINs entirely in your browser. Nothing generated by this tool is sent, saved or added to your history.

Generated locally in your browser

Build a secure password

Choose a preset or customise every setting. New values are created with the browser’s cryptographically secure random generator.

Quick presets

Random password settings

Allowed symbols / Other characters to exclude

Created on this device

Your generated results

Copy the value directly into a trusted password manager. Do not reuse it for another account.

Estimated strength–
Estimated entropy–
Approximate search space–
Available choices per position–
Result length–

Entropy is a mathematical estimate for values produced by this generator, not a promise of how long a real attack would take. Phishing, malware and password reuse bypass brute-force strength.

Private by design

Generation happens in JavaScript on this device. The tool does not transmit, log, store, analyse or place generated secrets in the page URL. Reloading the page removes them.

Only copy passwords on a trusted device. Browser extensions, malware or screen recording software may still be able to see what is displayed.

What makes this generator safer

Cryptographic randomness

The generator uses Web Crypto rather than Math.random(), and rejects biased random values before selecting characters or words.

Guaranteed character groups

When enabled, every selected character group appears at least once and the completed password is securely shuffled.

No secret history

Generated values are never written to localStorage, cookies, analytics events or shareable URLs by this tool.

Conservative guidance

The strength display focuses on length and estimated search space and does not claim a guaranteed crack time.

Practical password security checklist

  • Use a unique password for every account so one breach cannot unlock another service.
  • Save generated passwords in a reputable password manager rather than trying to memorise them.
  • Protect the password manager with a long master passphrase and multi-factor authentication.
  • Choose passkeys or phishing-resistant multi-factor authentication when a service offers them.
  • Never send a password by email, chat or a shared document.
  • Change a password when compromise is suspected; routine forced changes are not a substitute for unique strong passwords.

Security guidance and methodology

Current NIST guidance emphasises password length, unique passwords, password-manager support and permitting long passphrases. The Web Crypto API supplies cryptographically strong random values in modern browsers.

Secure Password Generator FAQ

Are passwords generated on the server?

No. This tool generates every password, passphrase and PIN locally in your browser. The generated value is not included in a request to the website.

Does the website save my generated password?

No. This tool does not write generated secrets to storage, cookies, analytics events or URLs. The visible result disappears when the page is reloaded.

Why is Web Crypto better than Math.random()?

Web Crypto is designed to provide cryptographically strong random values. Math.random() is useful for simulations and interface effects but is not suitable for generating secrets.

How long should a generated password be?

Twenty random characters is a strong practical default for many accounts. Use the longest unique password the service accepts and store it in a password manager.

Is a passphrase as secure as a random password?

It depends on how many words are chosen and the size of the source list. Randomly selected words can be strong, but short human-created phrases and famous quotations are predictable.

Should every password contain symbols?

For a randomly generated password, adding symbols increases the available character pool. Length and uniqueness are more important than predictable substitutions in a password chosen by a person.

What does entropy in bits mean?

It represents the approximate number of equally likely possibilities produced by the selected generator settings. Each additional bit doubles the theoretical search space.

Can I generate several passwords at once?

Yes. Choose one, five or ten results. Each value is generated independently with secure browser randomness.

Should I check a generated password against breach databases?

A sufficiently long value from a secure random generator is extremely unlikely to match a reused password. Sending a new secret to another service would create unnecessary exposure.

Is a PIN a replacement for a password?

Usually not. Numeric PINs have a much smaller search space and should be used only in systems that require them and enforce attempt limits or device protection.

Should I regularly change every password?

Change passwords after suspected compromise, accidental disclosure or a service breach. Unnecessary scheduled changes can encourage predictable variations and do not replace uniqueness.

What else protects an account?

Use multi-factor authentication or passkeys, keep devices updated, verify website addresses and watch for phishing. A strong password cannot protect against every attack.